Jump to content

office 365 single sign on (good idea or waste of time)


Recommended Posts

Posted

a lot of my schools (read probably all) are moving to office 365 as lln are going away :cheer2: . Now i quickly set it up in one school (they wanted email addresses asap so i just dumped ad users into a spreadsheet twiddle a bit and uploaded them so they now all have shiny new office 265 email). In the future (or possibly retroactively bearing in mind as usernames are in that schoo, staffab and office 365 are first.surname (and to complicate further a few have married name on 365 not in ad)) how easy and more importantly useful is it to set up sso?

 

If its a lot of faffing round to just skip 1 password is it worth it?

Posted

Pointless imo, our students and staff have no problem logging on to webmail when they need to.

 

Outlook client requires no login after the first setup.

 

Simples :)

Posted
Pointless imo, our students and staff have no problem logging on to webmail when they need to.

 

Outlook client requires no login after the first setup.

 

Simples :)

 

thats my take on it as well just wanted opinions looking into sso it looks like a right pita

Posted

We are going down the Office365 route as well. I saw the SSO option, but haven't decided as yet.

From a security point of view, we all know what certain members of staff can be like when it comes to leaving themselves logged in to a computer and walking away...

Posted
We are going down the Office365 route as well. I saw the SSO option, but haven't decided as yet.

From a security point of view, we all know what certain members of staff can be like when it comes to leaving themselves logged in to a computer and walking away...

 

stupidity/lazyness will always trump technology

Posted

This leads me on to another issue. One domain or two?

As all LLN schools were originally configured with two domains, one for Admin and one for Curriculum, and have a CISCO router to separate them, (which I assume LLN will want back) what are you doing about your domains when you leave LLN?

Posted (edited)
This leads me on to another issue. One domain or two?

As all LLN schools were originally configured with two domains, one for Admin and one for Curriculum, and have a CISCO router to separate them, (which I assume LLN will want back) what are you doing about your domains when you leave LLN?

 

i have as admin servers get replaced been moving them to a single network anyway just leaving a 2nd nic in the "admin" server for avco all thats all that half of the router does (unless they have voip)

 

school im at now has had a single domain for a few years im moving another to single domain at half term (admin server and 2-3 pcs wow that needs a domain lol) they even had a better spec dell server lying unused than their ye olde admin hp server

Edited by sted
Posted
thats my take on it as well just wanted opinions looking into sso it looks like a right pita

 

I did it in an afternoon. It's not that hard. The instructions that Microsoft provide on their website are pretty clear and comprehensive and will guide you through the process nicely. It means that your users will have to remember one less password which is always useful.

 

Plus once ADFS is set up, there's no reason why you couldn't use it for other services. We have it authenticating our Blackboard users and we're using a hosted service from them now.

Posted
I did it in an afternoon. It's not that hard. The instructions that Microsoft provide on their website are pretty clear and comprehensive and will guide you through the process nicely. It means that your users will have to remember one less password which is always useful.

 

Plus once ADFS is set up, there's no reason why you couldn't use it for other services. We have it authenticating our Blackboard users and we're using a hosted service from them now.

 

ok then do i need any extra hardware/

looking at it its the certificates stuff that puts me off and my domain is school.local and email is now longschoolname.co.uk iirc

Posted

Depends. I have it running on VMs so I didn't need any additional hardware. You could put it on existing member servers if you wanted to. You can't put the ADFS and ADFS proxy on the same box, you shouldn't out either onto a domain controller.

 

The only certificate that you need to worry about is the one that your ADFS server is published at. It will need to be a trusted cert from the likes of Verisign or Comodo (I got ours from Janet). It doesn't matter what your email domain or AD domain is called.

 

You will need to have the ADFS proxy on a publicly accessible IP address though, that may be your biggest difficulty. I don't know if it will work through a reverse proxy or not.

Posted
We have Office365 for students and it has crossed my mind a couple of times if we offer SSO but the negs outweigh the positives, such as they are relaying on us to authenticate for them. What happens if i want to do work on the servers over the weekend and restart the servers, students are then left without access to their emails.
Posted
Depends. I have it running on VMs so I didn't need any additional hardware. You could put it on existing member servers if you wanted to. You can't put the ADFS and ADFS proxy on the same box, you shouldn't out either onto a domain controller.

 

The only certificate that you need to worry about is the one that your ADFS server is published at. It will need to be a trusted cert from the likes of Verisign or Comodo (I got ours from Janet). It doesn't matter what your email domain or AD domain is called.

 

You will need to have the ADFS proxy on a publicly accessible IP address though, that may be your biggest difficulty. I don't know if it will work through a reverse proxy or not.

 

i have a single external ip address but thats atm used for my bodged set up to test then went live) terminal server but i could probably redirect the ports to the requisite server i have s 2008r1 box there doing jack (was the main server went wyrd was replaced now im trying to rehabilitate it as extra backup storage)

Posted
Do you have control of your external DNS as well?

 

personally no but i "think" the boss does as he sorted the mx records out but atm i doubt the url does owt its just for email

Posted

I do quite like the solution of DirSync with Password Sync, it's removed a lot of the "I can't remember my password because it's different from the computer" arguements we used to have and staff are being a bit more receptive to it. It's also the setup we dived straight in with on filtered OU's after the initial testing was complete and was very easy to go with.

 

The only thing some users don't particularly like is typing the whole email address in rather then just their username, however that is the least of my worries and not a fantastic reason to look at the SSO/ADFS route at the moment.

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...